|
|
Subscribe / Log in / New account

Study: Attacks on package managers

Study: Attacks on package managers

Posted Jul 15, 2008 9:43 UTC (Tue) by epa (subscriber, #39769)
In reply to: Study: Attacks on package managers by rrdharan
Parent article: Study: Attacks on package managers

That is the wrong approach.  You are suggesting there should be verification so that only
trustworthy people (by some measure) can set up a mirror site.  But it will always be possible
for bad guys to slip through the net.  Even the US nuclear weapons programme, with the
strictest possible vetting of participants, contained spies.

And even a well-meaning mirror site can be taken over by an attacker.

Better to make sure the update system is secure so that even with total control of one or more
mirrors an attacker cannot push out bad packages or cause a denial of service for more than a
few minutes.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds